Share on social networks!

Cybersecurity vacancies in Spain: why there are 30,000 unfilled while cyberattacks break records

Spain handled 122,223 cybersecurity incidents in 2025, 261% more than the previous year, according to data from National Cybersecurity Institute (INCIBE). This is the highest figure recorded to date, and it comes with another record: 237,028 vulnerable systems detected, of which more than 26,000 were new vulnerabilities and 4,200 were classified as critical.

This data coincides with a significant regulatory delay. The European NIS2 Directive, which requires thousands of Spanish companies to strengthen their cybersecurity, had a transposition deadline of October 17, 2024. As of mid-2026, it still has not become law in Spain.

SMEs, in the crosshairs

Of the total incidents handled in 2025, 601% affected small and medium-sized enterprises (SMEs)—organizations that, for the most part, do not have a dedicated security department. The private sector confirms the same trend from another angle: Check Point Research recorded an average of 2,105 cyberattacks per week per Spanish company in June 2026, 101% more than the previous year.

Cybersecurity vacancies, around 30,000 unfilled: a deficit that is not due to a lack of vocation

While the threat grows and legal requirements tighten, the market faces a different problem: cybersecurity vacancies in Spain continue to grow, with an estimated deficit of 30,000 unfilled positions and demand increasing between 20% and 20% each year.

And it's not a matter of economic attractiveness. Entry-level salaries in the sector (€20,000–€35,000 gross per year) already exceed the national average, and a junior SOC analyst position commands a similar or higher salary.

So why are so many cybersecurity vacancies still unfilled?

“For two years now, we’ve been seeing the same pattern in the selection processes of our partner companies: the training for these profiles has to be practical and realistic; they must be able to handle an incident from their very first day on the job. That’s the difference between a candidate who gets stuck in the interview stage and one who lands the job. The shortage of specialists is solved by having professionals who have received training aligned with the work environment before even joining the company.”

Jorge González, Head of Employability at EIP International Business School

Where is the real mismatch?

The problem isn't the number of people wanting to enter the sector; it's the type of training available compared to the actual cybersecurity vacancies that exist today. Companies need to fill very specific roles—incident response, regulatory compliance (NIS2, GDPR), cloud security, and OT security—and much of the traditional training remains focused on theory, not on simulating real-world scenarios.

This gap between theory and practice is also reflected in the certifications the market demands. The CISSP has become the benchmark for senior and management positions, while the OSCP leads in offensive environments, such as penetration testing. Both are now standard requirements, not just a way to differentiate oneself on a resume. The market is seeking professionals who have already managed the type of incident they will encounter on their first day of work.

cybersecurity eip 1

If you want to know how a training program specifically designed to address this gap is structured, you can consult the Master's Degree in Cybersecurity from EIP.

EIP International Business School

Hello
Subscribe to our newsletter to stay up to date with all the latest news

We don't spam! Read our Privacy Policy for more information.

Subscribe to our newsletter to stay up to date with all the news

EIP International Business School informs you that the data contained in this form will be processed by Mainjobs Internacional Educativa y Tecnológica, SAU as the controller of this website. The purpose of collecting and processing your personal data is to manage your newsletter subscription and to send you commercial information about the data controller's services. The legitimate basis for this is the explicit consent of the interested party. Data will not be transferred to third parties, except under legal obligation. You may exercise your rights of access, rectification, restriction, and deletion of data at cumplimiento@grupomainjobs.com, as well as the right to lodge a complaint with the supervisory authority. You can consult additional and detailed information on Data Protection in the Privacy Policy that you will find on our website.
Master Cybersecurity Professional Master

Leave a comment

EIP International Business School informs you that the data in this form will be processed by Mainjobs Internacional Educativa y Tecnológica, SAU as the party responsible for this website. The purpose of collecting and processing personal data is to manage your subscription to the newsletter as well as to send commercial information about the services of the data controller. The legitimacy is the explicit consent of the interested party. Data will not be transferred to third parties, except under legal obligation. You may exercise your rights of access, rectification, limitation and deletion of data at cumplimiento@grupomainjobs.com, as well as the right to lodge a complaint with the supervisory authority. You can consult additional and detailed information on Data Protection in the Privacy Policy that you will find on our website.